MycoFarm is built on a foundation of end-to-end encryption, on-site deployment options, and independently audited controls — so your grow data never leaves your control.
Security Pillars
All sensor telemetry, grow room data, and user records are encrypted with AES-256 at rest and TLS 1.3 in transit — from device edge to storage layer.
Data ProtectionDeploy the full MycoFarm stack inside your own network. No grow data — substrate logs, contamination flags, yield records — ever leaves your facility without explicit consent.
Data SovereigntyGranular RBAC with MFA enforced across all accounts. Assign growers, supervisors, and auditors exactly the permissions they need — no more, no less.
IdentityAutomated CVE scanning runs daily across all infrastructure. Critical findings trigger immediate remediation workflows with documented resolution timelines.
MonitoringEvery action — configuration changes, alert acknowledgements, data exports — is logged with actor, timestamp, and context. Logs are tamper-proof and exportable for regulatory review.
Audit TrailDefined response times for every severity tier: critical incidents are acknowledged within 1 hour, with status updates every 30 minutes until resolved.
ReliabilityHow We Protect Your Data
MycoFarm applies defence-in-depth: each layer — network, application, data, and physical — is independently hardened so that a compromise at one layer does not cascade across your operation.
Private VPC with strict ingress/egress rules, WAF, and DDoS mitigation on all public endpoints. No sensor data is routed over the public internet by default.
OWASP Top 10 remediation baked into our SDLC. All releases pass automated SAST, DAST, and dependency-check pipelines before deployment.
Each farm's data is logically isolated at the database level. Multi-tenant environments use row-level security; on-premise deployments are fully air-gapped by default.
On-site hardware ships pre-hardened with signed firmware, disabled unnecessary services, and automatic security patch delivery over an authenticated update channel.
Compliance & Certifications
Independently audited security controls covering availability, confidentiality, and processing integrity — report available on request.
Full alignment with Canada's Personal Information Protection and Electronic Documents Act for any data touching Canadian growers or consumers.
Data subject rights, lawful processing bases, and EU data residency options for operations exporting to European markets.
Automated, tamper-proof logging of all critical control points — structured to satisfy CFIA, USDA, and EU food safety audit requirements.
Input tracking and chain-of-custody records built to satisfy CGSB-32.310 and 32.311 audit requirements without manual paperwork.
Third-party red-team exercises conducted annually. Findings and remediation timelines are shared with enterprise customers under NDA.
Granular access policies ensure team members see only the rooms, data sets, and controls appropriate to their role.
Configurable retention policies let you define how long sensor, yield, and compliance records are kept — with automated purge or export on schedule.
Responsible Disclosure
If you discover a security issue in MycoFarm, we want to hear from you. Email us at security@mycofarm.io with a description of the issue, steps to reproduce, and any proof-of-concept.
We acknowledge all reports within 24 hours and commit to a full triage response within 5 business days. We do not pursue legal action against good-faith security researchers.
security@mycofarm.ioOur security team operates on clearly defined SLAs for every severity tier.
Active data breach or system compromise. Full incident team mobilised immediately.
Severe vulnerability with potential for exploitation. Patch released within one business day.
Moderate risk without active exploitation. Addressed in the next scheduled release cycle.
Informational findings and hardening opportunities. Tracked and resolved in quarterly cycles.
Get started
Our security team is available to walk enterprise customers through our controls, share audit reports, and scope custom deployment architectures.